fabric CA client user enrolment authorisation failure

Viewed 4107

I am trying to enroll admin after initialising fabric CA server with:

 fabric-ca-server init -b “admin:adminpw”

And starting CA server with:

fabric-ca-server start -b “admin:adminpw”

At client-side, enroll command:

fabric-ca-client enroll -u http://admin:adminpw@localhost:7054

Client-side error message:

[INFO] generating key: &{A:ecdsa S:256}
[INFO] encoded CSR
Error: Response from server: Error Code: 20 - Authorization failure

Server-side:

fabric-ca-server start -b “admin:adminpw”
2018/08/27 14:48:57 [INFO] Configuration file location: 
/home/nadeem/Documents/Fabric-CA/server/fabric-ca-server-config.yaml
2018/08/27 14:48:57 [INFO] Starting server in home directory: 
/home/nadeem/Documents/Fabric-CA/server
2018/08/27 14:48:57 [INFO] Server Version: 1.2.1-snapshot-3bcdbb2
2018/08/27 14:48:57 [INFO] Server Levels: &{Identity:1 Affiliation:1 
Certificate:1 Credential:1 RAInfo:1 Nonce:1}
2018/08/27 14:48:57 [INFO] The CA key and certificate already exist
2018/08/27 14:48:57 [INFO] The key is stored by BCCSP provider 'SW'
2018/08/27 14:48:57 [INFO] The certificate is at: 
/home/nadeem/Documents/Fabric-CA/server/ca-cert.pem
2018/08/27 14:48:57 [INFO] Initialized sqlite3 database at 
/home/nadeem/Documents/Fabric-CA/server/fabric-ca-server.db
2018/08/27 14:48:57 [INFO] Home directory for default CA: 
/home/nadeem/Documents/Fabric-CA/server
2018/08/27 14:48:57 [INFO] Listening on http://0.0.0.0:7054
***2018/08/27 14:49:34 [INFO] 127.0.0.1:46350 POST /enroll 401 23 "Failed 
to get user: : scode: 404, code: 63, msg: Failed to get User: sql: no 
rows in result set"***

fabric-ca-client/server:

Version: 1.2.1-snapshot-3bcdbb2 Go version: go1.11 OS/Arch: linux/amd64

Found similar post here:

https://jira.hyperledger.org/browse/FABC-302

It is marked resolved with v1.2 but there are no clear instructions on how to resolve it now. Thanks :)

4 Answers

I've been trying to make Fabric-CA work for a while, The best advice I can give you is to take off the "" around the admin credentials before you start. I do not put them and it works for me. So commands would be :

fabric-ca-server init -b admin:adminpw

fabric-ca-server start -b admin:adminpw

this error message appear. Account and password are not same when ca start and when you use ca enroll use.

Error Code: 20 - Authorization failure

Error code 20 arises due to the following condition. Suppose you have registered the identity like this :-

fabric-ca-client  register --id.name org1 --id.type client --id.affiliation org1 --id.attrs '"hf.Registrar.Roles=user,client,peer","hf.AffiliationMgr=true","hf.Revoker=true"'

which is giving you the output

2020/02/05 11:19:25 [INFO] Configuration file location: /home/username/myPros/caclient/admin/fabric-ca-client-config.yaml
Password: ZXCbhJajCObX

and you are trying to enroll the user/identity like this :-

fabric-ca-client enroll -u http://org1-admin:ZXCbhJajCObX@localhost:7054

or

fabric-ca-client enroll -u http://org1-admin:adminpw@localhost:7054

so long story short either your enrollment Id or your password is mismatched. Make sure that your username and password are not mismatched.

Possibly during init. Look in your fabric-ca-server-config.yaml file for these quotation marks and remove them. Do not use them during init enroll.

image of fabric-ca-server-config.yaml file

Related